rabbyy[.]myftp[.]org
“Rabby Wallet | Your Go-to Wallet for Ethereum and EVM”
rabbyy.myftp.org — Неперевірений. Уособлення бренду: Across; Тип шахрайства: Fake Airdrop. Зведення доказів: VirusTotal 0/91; URLQuery 1 alert; PhishDestroy score 57/100. Реєстратор: "Vitalwerks Internet S….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain www.rabbyy.myftp.org is a phishing site engaged in brand impersonation, specifically targeting users of the 'across' platform. It presents itself as a legitimate Rabby Wallet service for Ethereum and EVM chains but operates as an airdrop scam and wallet-connect phishing scheme. No crypto drainer kit was identified. The site is currently taken offline, but its prior activity posed an elevated risk to victims who may have connected wallets or shared credentials.
Technical indicators confirm the malicious nature of www.rabbyy.myftp.org. The domain was flagged by 1 of 95 VirusTotal security vendors, including Ermes, and appears on 1 security blocklist (PhishDestroy). It was registered through Vitalwerks Internet Solutions, LLC DBA No-IP on February 21, 2026, and resolves to the IP address 216.198.79.1, hosted in the US under AS16509 (Amazon.com, Inc.). No SSL certificate was issued, and the observed page title was 'Rabby Wallet | Your Go-to Wallet for Ethereum and EVM'. Nameservers include nf1.no-ip.com, nf2.no-ip.com, nf3.no-ip.com, and nf4.no-ip.com. Gridinsoft assigned a trust score of 0/100 to the domain.
Victims of www.rabbyy.myftp.org should immediately revoke any token approvals granted to the site and transfer funds to a new wallet to prevent unauthorized access. If credentials were entered, change passwords for all associated accounts and enable two-factor authentication (2FA). Monitor accounts for suspicious activity and report the phishing domain to platforms like Google Safe Browsing, PhishTank, or the impersonated brand's security team for further action.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | www.rabbyy.myftp.org/assets/index-ourwc5_u.js |
malware | Detects file containing Telegram Bot API |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога